Impact
Dell OpenManage Server Administrator software prior to version 11.1.0.2 contains an Improper Authentication weakness. An attacker who can reach the remote management interface may log in without valid credentials, enabling them to carry out administrative actions on the host.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node on several platforms: RHEL 8.10, RHEL 9.4, SLES 15, and a patched Windows Managed Node version. Only installations running a version earlier than 11.1.0.2 are impacted; later releases include the fix.
Risk and Exploitability
With a CVSS score of 7.7, the risk is considered high. The description states that an unauthenticated attacker can reach the remote service, implying a network‑based, remote attack vector. EPSS data is not available, and the vulnerability is not yet listed in CISA's KEV catalog, reducing confidence in active exploitation but still indicating a serious potential. Organisations that expose OMSA to external networks or have inadequate network segmentation face a clear pathway for unauthorized access.
OpenCVE Enrichment